Headline
GHSA-mj5w-w588-j6xg: Use of Hard-coded Credentials in AgileConfig.Client
Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.
Use of Hard-coded Credentials in AgileConfig.Client
Critical severity GitHub Reviewed Published Aug 19, 2022 • Updated Aug 30, 2022
Related news
CVE-2022-35540: security vulnerability (存在安全漏洞) · Issue #91 · dotnetcore/AgileConfig
Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.